Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

SMS to me is solely the channel for machines to force a bad MFA implementation on me and couriers to tell me something is on the way/nearly there/delivered. All person to person comms, without exception, iPhone or Android users, is via WhatsApp. Anecdata from UK.


I agree that SMS is obsolete, but I will not so willingly jump to another zuckerberg platform


I think the argument about SMS being insecure is very real but exaggerated. We send password reset with capability URLs through non encrypted mail. Sure, the channel is most likely encrypted but anyone at mail service providers could easily take over a massive amount of accounts. Although the user would notice at least.

Sure, there are tools to intercept SMS without the user noticing, but as a second factor an attacker still doesn't have access to other factors.

The successor RCS has the problem that users cannot reset the password. If you are compromised you need to urgently contact your ISP.


To be clear, I don't consider it to be bad for primarily security reasons, I consider it to be bad because it's inconvenient when it's the only option and forced. I would always prefer TOTP or a push based system such as WhatsApp or telegram or similar. SMS can be slow, and uses an application I don't open for any other purpose.


I far, far prefer a protocol over Zuckerware, but to each their own.


If the current dumb phone comeback continues, SMS won't be going anywhere any time soon


Same, from the US


Really? iMessage is very much used in the USA.


I guess not where I’ve lived (chicago, sf)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: